More Open Source Startup Podcast episodes

E195: Taking on the New AI Attack Surface With Manifold: Runtime, Skills & Supply Chains thumbnail

E195: Taking on the New AI Attack Surface With Manifold: Runtime, Skills & Supply Chains

Published 26 May 2026

Duration: 00:45:18

AI security is shifting from controlling model outputs to securing autonomous AI actions through runtime monitoring, addressing challenges like third-party "skills," inventory gaps, and access control, while emphasizing tools like LM Guard and community-driven practices to manage evolving risks in AI-driven workflows.

Episode Description

The latest Open Source Startup Podcast episode has our co-hosts Robby and Tim in conversation with Neal Swaelens and Oleks Yaremchuk, 2 of the Co-Foun...

Overview

The podcast discusses the evolution of AI security, focusing on the work of Neil and Alex, who transitioned from securing model outputs to addressing broader challenges as AI systems became more autonomous. Neils background in finance and product management included securing vision models against adversarial attacks, while Alexs engineering expertise and open-source contributions led to the development of LM Guard, a widely adopted tool for detecting malicious AI responses. The pair later co-founded Manifold Security to address the growing need for securing AI-driven actions, such as executing tasks or interacting with endpoints, rather than just model outputs. They highlight a market shift toward runtime security, as traditional guardrail-based approaches fail to address the complexity of agents, including their interactions with external systems and supply chain risks. This transition is compounded by the lack of visibility into agent behavior and third-party components, creating new vulnerabilities that existing security frameworks cannot resolve.

The conversation emphasizes challenges in runtime security, including the difficulty of monitoring AI agents actions, detecting risks in real time, and managing supply chain exposure from open-source skills and libraries. Manifolds approach centers on runtime detection and response, leveraging supply chain transparency and inventory management to address gaps in enterprise readiness. Lessons from prior projects like LM Guard are applied to build open-source foundations that balance usability and security, with a focus on enabling cross-functional teams through accessible tools. The podcast also critiques existing vendors for generating noise and insufficient actionable insights, underscoring the need for frameworks that provide context-aware analysis of agent behavior and alternative recommendations to mitigate risks. Finally, it stresses the importance of community engagement, clear value propositions, and adapting legacy security practices to meet the evolving demands of AI-driven systems.

What If

  • What if you built an open-source runtime monitoring tool for AI agents, focused on detecting unauthorized API or endpoint interactions?

    • Concrete move: Develop a lightweight agent that hooks into common AI agent frameworks (e.g., LangChain, AutoGen) to log and analyze invocation chains, flagging risky actions like unauthorized API calls or file writes.
    • Why now: With enterprises rapidly adopting AI agents for autonomous tasks (e.g., DevOps, customer support), runtime security gaps are urgent. Existing tools focus on model outputs, not agent actions.
    • Expected upside: Early adopters (engineering teams) may adopt it for compliance, leading to community traction and partnerships with cloud providers or enterprise security platforms.
  • What if you created an agent inventory tool to map and audit all AI agents, skills, and dependencies across a companys infrastructure?

    • Concrete move: Build a CLI or integration for cloud platforms (e.g., AWS, Azure) to scan for deployed agents, track their dependencies, and generate a risk dashboard (e.g., "unknown skills," "untrusted authors").
    • Why now: Enterprises lack visibility into their AI agent ecosystems, leading to unmitigated supply chain risks. Manifests ecosystem graph aligns with this need.
    • Expected upside: Enterprises might adopt it as a foundational layer for governance, enabling monetization via SaaS subscriptions or integrations with enterprise security workflows.
  • What if you launched a framework to evaluate AI agent "skills" using execution graphs and lineage analysis, similar to how LM Guard analyzed model outputs?

    • Concrete move: Create an open-source tool that parses agent skill manifests, maps execution paths, and flags risky behavior (e.g., writing to system files) using community-curated rules.
    • Why now: Skills are proliferating as AI agent components, but theres no standard for evaluating their trustworthiness. Competitors like Ciscos scanners fail to provide actionable insights.
    • Expected upside: Developers might adopt it for secure skill deployment, while security teams could use it to reduce noise in their workflows, driving adoption in regulated industries.

Takeaway

  • Build an open-source runtime security tool for AI agents: Focus on detecting and mitigating risks during execution, such as unauthorized API calls or endpoint interactions, by analyzing agent behavior in real time (inspired by LM Guard's success in text-based threat detection).

  • Prioritize supply chain visibility tools for AI agent components: Create a tool to map and audit agent dependencies, external assets, and third-party skills, enabling risk assessment and inventory management (addressing the "massive untapped supply chain" challenge mentioned in the text).

  • Adopt an open-core model with early community engagement: Define your open-source projects scope and licensing strategy upfront, using community feedback to refine features and validate product-market fit (learned from LM Guards approach to avoid ambiguity and maintain competitive differentiation).

  • Develop runtime posture management (RPM) for agent security: Build tools that analyze full invocation chains and contextual interactions (not isolated events) to detect risks in AI agents, addressing the gap between existing tools and modern agent security requirements.

  • Create a dual-purpose platform with open-source and commercial tiers: Design a solution that offers free, open-source components for community adoption while packaging premium features (e.g., enterprise reporting, supply chain risk scoring) for commercialization, aligning with Manifests strategy to drive network effects and enterprise readiness.

Recent Episodes of Open Source Startup Podcast

3 Aug 2026 E201: Building Your Agent Army with Paperclip

Recommended: Try and use agent frameworks

"Paperclip is an open-source AI agent management tool for work, offering task automation, accountability, and scalability with human-centric design and future enhancements like automated reviews and specialized manager agents."

27 Jul 2026 E200: Open Sourcing Warps Terminal

"Warp, an AI-driven terminal and cloud automation platform, enhances developer productivity with open-source tools, proprietary agentic workflows, and a focus on scalable, vendor-neutral software development."

3 Jun 2026 E196: Shifting Developer Portals to Agent Portals with Port

Port is an agentic engineering platform streamlining developer workflows through AI-driven automation, self-service infrastructure, cloud resource management, and integration with Kubernetes and observability systems, offering a cohesive enterprise solution with open-sourced integrations and proprietary features to address fragmented tools, scalability, and AI workflow governance.

More Open Source Startup Podcast episodes